Record summary

CVE-2022-24905 has a selected CVSS score of 4.3 (medium).

Description

Argo CD is a declarative, GitOps continuous delivery tool for Kubernetes. A vulnerability was found in Argo CD prior to versions 2.3.4, 2.2.9, and 2.1.15 that allows an attacker to spoof error messages on the login screen when single sign on (SSO) is enabled. In order to exploit this vulnerability, an attacker would have to trick the victim to visit a specially crafted URL which contains the message to be displayed. As far as the research of the Argo CD team concluded, it is not possible to specify any active content (e.g. Javascript) or other HTML fragments (e.g. clickable links) in the spoofed message. A patch for this vulnerability has been released in Argo CD versions 2.3.4, 2.2.9, and 2.1.15. There are currently no known workarounds.

Description source: CVE List

Exploitation context

CISA SSVC decision

ExploitationNone
AutomatableNo
Technical impactPartial

CISA Coordinator · SSVC 2.0.3 · Evaluated Apr 23, 2025 · Source: CVE List

Affected products and versions

3
ProductSourceVersion rangeStatus
CVE List< 2.1.15affected
>= 2.2.0, < 2.2.9affected
>= 2.3.0, < 2.3.4affected

github.com/argoproj/argo-cd

Browse Go / github.com/argoproj/argo-cd
GitHub AdvisoryBefore 2.1.15 · Fixed in 2.1.15affected

github.com/argoproj/argo-cd/v2

Browse Go / github.com/argoproj/argo-cd/v2
GitHub Advisory2.3.0 to < 2.3.4 · Fixed in 2.3.4affected
2.2.0 to < 2.2.9 · Fixed in 2.2.9affected
2.0.0 to < 2.1.15 · Fixed in 2.1.15affected

References

5